<?php
/*
 * code to effect changes to project
*/
include("../inc_files/utils/checksession.php");
// Create connection
include("../inc_files/utils/dbconnection.php");

//sanitise the input data
$title = $mysqli->real_escape_string($_POST['title']);
$startDate = $mysqli->real_escape_string($_POST['startdate']);
$endDate = $mysqli->real_escape_string($_POST['enddate']);
$budget = $mysqli->real_escape_string($_POST['budget']);
$projectID = $mysqli->real_escape_string($_POST['projectid']);
$taskID = $mysqli->real_escape_string($_POST['taskid']);
$percentComplete = $mysqli->real_escape_string($_POST['percentcomplete']);

//convert the dates into a format compatible with MySQL

$startDate = formatdate($startDate);
$endDate = formatdate($endDate);

if($taskID == 'new'){
	$query="INSERT INTO tasks (Title,StartDate,EndDate,Budget,Project,PercentComplete)
	VALUES
	('$title','$startDate','$endDate','$budget','$projectID', $percentComplete)";
} else {
	$query="UPDATE tasks SET Title = '$title',
	StartDate = '$startDate', EndDate = '$endDate',
	Budget = '$budget',PercentComplete = '$percentComplete' WHERE TaskID = '$taskID'";

}
$mysqli->query($query) or die($mysqli->error);

//tidy up database connection
$mysqli->close();

//function to convert dates from dates entered by the user
//to dates for MySQL
function formatdate ($date){
	$datearray = explode('/' , $date);
	$date = $datearray[2].'-'.$datearray[1].'-'.$datearray[0];
	return $date;

} 
?>